ISO/IEC 27001:2022
What is ISO 27001?
ISO/IEC 27001:2022 sets requirements for establishing, implementing, maintaining, and continually improving an information security management system. The International Organization for Standardization and the International Electrotechnical Commission publish this globally recognized standard. The 2022 revision of ISO 27001 organizes controls into four categories: Organizational, People, Physical, and Technical.
Who is the intended audience?
ISO/IEC 27001:2022 is for organizations of any size, in any industry, that want a framework for measuring and improving their information security program. Formal ISO/IEC 27001 certification is an industry-recognized way to show your organization’s commitment to information security best practices.
Where can I find more information?
More information on ISO/IEC 27001:2022 is on the ISO website.
How can runZero help me with these controls?
runZero helps most with the Organizational and Technical controls of ISO/IEC 27001:2022. The tables below describe how runZero supports each relevant control.
Organizational controls
| No. | Control | runZero capability |
|---|---|---|
| 5.9 | Inventory of information and other associated assets | runZero inventories assets through active scanning, passive discovery, and API integrations, with detailed fingerprinting of IT, OT, and IoT devices across on-prem, cloud, and remote environments. (Playbook) |
Technical controls
| No. | Control | runZero capability |
|---|---|---|
| 8.1 | User endpoint devices | Through active scanning, passive sampling, and API integrations, runZero can find gaps in user endpoint device controls, including: |
| 8.7 | Protection against malware | Through integrations with endpoint protection platforms, runZero can discover: |
| 8.8 | Management of technical vulnerabilities | Through active scanning, passive sampling, and API integrations, runZero supports technical vulnerability management, including: |
| 8.9 | Configuration management | Using active scanning and passive sampling, runZero can monitor configuration baselines by discovering: |
| 8.20 | Network security | runZero can discover and fingerprint both managed and unmanaged network devices through active scanning and passive sampling. With service probing, runZero can also identify weak security configurations and vulnerable firmware versions. |
| 8.21 | Security of network services | Using active scanning and passive sampling, runZero can discover network services and their risks, including: |
| 8.22 | Segregation of networks | To test network segmentation, place an Explorer outside a security zone and scan into it; the results show which assets and services are exposed. runZero can also identify multi-homed assets and potential network bridges. |
| 8.24 | Use of cryptography | runZero supports cryptography and key management best practices by discovering: |